Security Advisory – April, 2024: Neat Statement on the XZ Utils Vulnerability
Advisory ID: NEAT-SA-2024-04-12
Publication date: April 12, 2024
Last updated: April 12, 2024
Severity: Critical — CVSS v3.1 Base Score: 10.0 (severity of the underlying XZ Utils vulnerability; Neat determined it does not affect Neat products)
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (Red Hat scoring, via NVD)
CVE ID: CVE-2024-3094
Summary
Malicious code was deliberately inserted into XZ Utils, a widely used open-source compression library included in many Linux distributions. The backdoor targets the SSH daemon authentication process and could allow a remote attacker to execute arbitrary code on an affected machine. It affects XZ Utils versions 5.6.0 and 5.6.1 when installed from a complete package download.
Affected Products
None. Neat completed an internal investigation and determined that the XZ Utils vulnerability does not affect Neat products.
Impact
Not applicable to Neat products. For organizations directly running an affected version of XZ Utils, the vulnerability could allow a remote attacker to execute arbitrary code via the SSH authentication process.
Details
The backdoor is believed to have been deliberately introduced by one of the XZ Utils project maintainers. It is present only in a complete package download of versions 5.6.0 and 5.6.1, not in the standard Git source repository.
Remediation
No action is required for Neat products. Organizations running XZ Utils 5.6.0 or 5.6.1 directly should update per guidance from their Linux distribution.
Acknowledgements
Not applicable — identified and reported by the open-source security community.
References
- The Hacker News — Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution
- NSFOCUS — XZ Utils Backdoor Vulnerability (CVE-2024-3094) Advisory
- CVE-2024-3094 — National Vulnerability Database
Contact
Questions about this advisory can be directed to security@neat.no.